Webkul
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Webkul product.
RSS Feeds for Webkul security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Webkul products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Webkul Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 33 vulnerabilities in Webkul with an average score of 6.4 out of ten. Last year, in 2025 Webkul had 7 security vulnerabilities published. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.72.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 33 | 6.38 |
| 2025 | 7 | 5.66 |
| 2024 | 13 | 7.14 |
| 2023 | 9 | 6.51 |
| 2022 | 1 | 6.10 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 8.80 |
It may take a day or so for new Webkul vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Webkul Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-93988 | Sep 19, 2026 |
QloApps 1.7.0 Path Traversal via admin/ajax.php getEmailHTMLQloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data. |
|
| CVE-2026-93454 | Sep 17, 2026 |
Aureus ERP <1.6.0 XSS via Untrusted Payment Term Note FieldAureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record. |
|
| CVE-2026-92234 | Sep 15, 2026 |
QloApps 1.7.0 XSS via child_features in back-officeQloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter. |
|
| CVE-2026-90944 | Sep 14, 2026 |
Krayin CRM 2.2.6 Unauthenticated Email Injection via /admin/mail/inbound-parseKrayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads. |
|
| CVE-2026-89268 | Sep 12, 2026 |
QloApps <=1.7.0 XSS via list helper POST filter unescapedQloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions. |
|
| CVE-2026-85395 | Sep 03, 2026 |
UnoPim <2.1.3: ACL Bypass Enables Unlimited OAuth & Permission EscalationUnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware. |
|
| CVE-2026-75498 | Aug 25, 2026 |
SQLi in Webkul QloApps Address.php via bo_query paramWebkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c. |
|
| CVE-2026-75497 | Aug 25, 2026 |
SQL Injection in Webkul QloApps via unsanitized bo_query param (CustomerMessage.php)Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c. |
|
| CVE-2026-75496 | Aug 25, 2026 |
QloApps: Inadequate File Extension/MIME Validation Leads to RCEWebkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c. |
|
| CVE-2026-75082 | Aug 18, 2026 |
Bagisto 2.4.4 XSS in Customer-Registration Email (first_name/last_name)A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-75081 | Aug 17, 2026 |
Webkul Bagisto <=2.4.4 RMA Argument Manipulation (Remote)A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19997 | Aug 17, 2026 |
Bagisto <=2.4.4 RMA Endpoint Auth Byp @ /admin/sales/rma/requestsA security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19996 | Aug 17, 2026 |
Bagisto <=2.4.4: /admin/customers Improper Privilege Escalation (Remote)A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19995 | Aug 17, 2026 |
Webkul Bagisto <=2.4.4 RMA Message Handler XSSA vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19994 | Aug 17, 2026 |
Auth Bypass in Bagisto 2.4.4 via Config Mgmt 'action'A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19993 | Aug 17, 2026 |
Webkul Bagisto <=2.4.4 RMA State Validation Remote Workflow ExploitationA vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19838 | Aug 14, 2026 |
Bagisto <2.4.4 Auth Bypass via Backend Reporting EndpointA security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19837 | Aug 14, 2026 |
Bagisto 2.4.4 Customer Search Info Disclosure via Query ParamA weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19836 | Aug 14, 2026 |
Bagisto <=2.4.4 Auth Bypass via /admin/customers/view IDA security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19835 | Aug 14, 2026 |
Webkul Bagisto 2.4.4 Improper Access Control in Customer Item Deletion EndpointA vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-19834 | Aug 14, 2026 |
Webkul Bagisto <=2.4.4 AdminCustomerImpersonation Auth Bypass via IDA vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." |
|
| CVE-2026-41453 | Aug 03, 2026 |
Krayin CRM before 2.2.4 blind SQLi in LeadDataGridKrayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data. |
|
| CVE-2026-60120 | Jul 09, 2026 |
Bagisto 2.4.3 XSS via clientside template injection in create.blade.phpBagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer. |
|
| CVE-2017-20262 | Jun 19, 2026 |
SQLi in Joomla! Ajax Quiz 1.8 via cid paramJoomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract sensitive database information including table names and column structures. |
|
| CVE-2026-25558 | Jun 08, 2026 |
QloApps <1.7.0 XSS via SVG in admin file managerQloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file. |
|
| CVE-2026-9506 | Jun 08, 2026 |
Bagisto ImageCacheController Path Traversal Remote File ReadThis vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system. Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system. |
|
| CVE-2026-25861 | Jun 02, 2026 |
QloApps 1.7.0 MD5 Hashing Vulnerability in Tools::encrypt()QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial. |
|
| CVE-2026-36341 | May 07, 2026 |
Webkul Krayin CRM 2.1.5 XSS in /admin/activities/create Comment FieldCross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint |
|
| CVE-2026-38532 | Apr 14, 2026 |
Webkul Krayin CRM 2.2 BOLA: Unauthorized Contact AccessA Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. |
|
| CVE-2026-38526 | Apr 14, 2026 |
Webkul Krayin CRM 2.2.x - Auth Aut File Upload via /admin/tinymce/uploadAn authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. |
|
| CVE-2026-38527 | Apr 14, 2026 |
SSRF in Webkul Krayin CRM 2.2.x /settings/webhooks/create internal scanA Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. |
|
| CVE-2026-38529 | Apr 14, 2026 |
Broken OLL in Webkul Krayin CRM v2.2.x /Settings/UserController.phpA Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. |
|
| CVE-2026-38530 | Apr 14, 2026 |
Webkul Krayin CRM v2.2.x BOLA in LeadController.php allows lead data accessA Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. |
|
| CVE-2025-10759 | Sep 21, 2025 |
Webkul QloApps <1.7.0 CSRF Token Handler Auth BypassA vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We are already aware about this vulnerability and our Internal team are already working on this issue. (...) We'll implement the fix for this vulnerability in our next major release." |
|
| CVE-2025-29009 | Jul 16, 2025 |
Unrestricted Upload Vulnerability in Medical Prescription Plugin v1.2.3 (WooC)Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <= 1.2.3. |
|
| CVE-2025-6173 | Jun 17, 2025 |
SQLi in Webkul QloApps 1.6.1 admin/ajax_products_list.phpA vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release. |
|
| CVE-2025-3568 | Apr 14, 2025 |
CVE-2025-3568 Webkul Krayin CRM <=2.1.0 XSS in SVG HandlerA vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE. |
|
| CVE-2025-26058 | Feb 18, 2025 |
Webkul QloApps 1.6.1 Auth Token Exposure via URL RedirectionWebkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. |
|
| CVE-2025-1155 | Feb 10, 2025 |
Webkul QloApps 1.6.1 XSS in Your Location Search (stores)A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term. |
|
| CVE-2025-1074 | Feb 06, 2025 |
Webkul QloApps 1.6.1 CSRF via logout URL HandlerA vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. They are aware about it and are working on resolving it. |
|
| CVE-2024-11281 | Dec 25, 2024 |
WooCommerce Point of Sale Plugin Privilege Escalation VulnerabilityThe WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. This makes it possible for unauthenticated attackers to change the email of arbitrary user accounts, including administrators, and reset their password to gain access to the account. |
|
| CVE-2024-52305 | Nov 13, 2024 |
UnoPim Laravel Framework SVG File Upload Session Hijacking VulnerabilityUnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5. |
|
| CVE-2024-50637 | Nov 06, 2024 |
UnoPim 0.1.3 XSS via SVG in Create UserUnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies. |
|
| CVE-2024-45932 | Oct 07, 2024 |
XSS in Krayin CRM v1.3.0 via org name field (/admin/contacts/organizations/edit/2)Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. |
|
| CVE-2024-46366 | Sep 27, 2024 |
CSTI in Webkul Krayin CRM 1.3.0 allows remote clientside code executionA Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. |
|
| CVE-2024-46367 | Sep 27, 2024 |
Stored XSS in Webkul Krayin CRM 1.3.0 via Username FieldA Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. |
|
| CVE-2024-40318 | Jul 25, 2024 |
QloApps 1.6.0.0: Arbitrary File Upload (CVE-2024-40318)An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. |
|
| CVE-2023-36238 | Mar 13, 2024 |
Bagisto 1.5.1 IDOR via Invoice ID ParameterInsecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter. |
|
| CVE-2024-27499 | Mar 01, 2024 |
Bagisto 1.5.1 XSS via PNG upload in product reviewBagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. |
|
| CVE-2023-36237 | Feb 26, 2024 |
Bagisto <=1.5.1 CSRF allows arbitrary code executionCross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script. |
|